Grok handling logs with less information

Hello again, I need an assistance on how could I extract logs with less information. For instance regular logs have full information while some logs have shorter information (see below), I tried adding two formats in grok, but it seems not able to parse logs with less information. Thank you in advance.
Regular logs: <164> http_scan: 1234567890 1 x99.xx.1xx.2xx application/x-protobuf 230 BYF ALLOWED CLEAN 2 0 0 0 0 (-) 0 - 0 - 0 business [ldap0:user01] business 0

other logs: <164> http_scan: 1234567890 1 x99.xx.1xx.2xx image/jpeg 14067 BYF ALLOWED CLEAN 0

Never mind, I figured it out. Thanks

@John_Lim - Can you share what you did? I am curious to know.


This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.